Opens in a new tab
All articles
4. 2. 2018
2 min read

5 obligations for businesses arising from the GDPR

Data protection, pseudonymisation, record keeping, data protection officer and immediate reporting of data breaches. These are the five most important obligations for businesses that the GDPR will bring in May.


The European Union’s new General Data Protection Regulation (GDPR), which will come into force in May, brings a number of changes. It regulates not only the rights of citizens but also the obligations of businesses.

The GDPR will affect completely all companies with more than one employee. It may not even work on the internet. Businesses will have to make huge investments in software and process modifications in their companies. The following lines summarize the five most important obligations that the introduction of the GDPR implies for businesses.

Data protection
GDPR expands the definition of personal data. New personal data will also include email, phone number, photographic record, IP address or the much-discussed cookies. The Regulation also adds a new category of so-called genetic and biometric data. These data, as well as data on racial or ethnic origin, political opinions, health or sexual orientation, will only be processed under a very strict regime.

Pseudonymisation
Pseudonymisation of personal data is a process whereby identity is hidden. The aim of pseudonymisation is to be able to retrieve further details of an individual without needing to know exactly who they are. Various keys and encryption are used to do this.

Record keeping
From May, data controllers will no longer have to comply with the so-called notification obligation with the Data Protection Authority (DPA) before they start processing that data. But they will now have to keep records of all activities related to the processing of the data.

Data Protection Officer
In particular, the GDPR introduces a new function of independent controller, the Data Protection Officer (DPO), into corporate life. His/her main task will be to monitor the compliance of personal data processing with the obligations arising from the GDPR. In addition, the DPO will conduct internal audits, train staff and take care of the entire internal data protection agenda.

Reporting of stolen data
Every serious data breach, every data theft and every unauthorized access to personal data will be reported by data controllers within 72 hours at the latest. So it should no longer be the case that we only learn about such cases of massive personal data leakage after several years.

Hold the key to proper data processing and data security in your hands If you encounter any confusion regarding any of these obligations, please do not hesitate to contact us. We will be happy to advise you.

Have a project?

Get in touch and we'll discuss how we can help.
Contact us

More articles

1 Aug 2026

Cyber Resilience Act: New Rules for Secure Software and Digital Products

The European Union is introducing another important regulation in the field of cybersecurity. It is called the Cyber Resilience Act, or CRA for short, and applies to all products with a digital component. This means not only smart devices, but also software, applications, and systems that connect to a network or communicate with another service…
Read the article
15 Jul 2026

Withdrawal button – Wontilles responds in advance to new legislative requirements

The legislative environment in the field of e-commerce is undergoing constant changes, which place high demands on online shop operators.
Read the article
1 Jun 2026

Railsformers at the Faculty of Arts at the OU: Ruby on Rails in practice and now also in IT business

At the Faculty of Science of the University of Ostrava, we have long been giving students practical experience with Ruby on Rails development and showing them what it looks like to work on real web applications. From the original pilot course, we have developed a stable course Ruby on Rails I and II, which we…
Read the article